My guy @ManyKeys would like to have a word with you about firmware and ensuring your physical hardware isn't compromised.
not clear how that is done exactly, so we might be fucked.
Login to reply
Replies (3)
Note too that when you get into firmware backdoors, you're getting into expensive targeted attack territory. Mainly with compromised trusted execution environments and trusted encryption chips. Passive surveillance is nearly impossible at this level and thus, for most threat models, a spyware free Linux distro and GrapheneOS is more than sufficient for extremely strong privacy guarantees for most.
If you're hiding thousands of Monero from state actors then you're going to want Libreboot + Kicksecure live mode + Veracrypt hidden volume for wallet files or something similar. As your threat model decreases you can compromise on these measures.
Honorary mention to puri.sm too they also have similar offerings to system76.
Libreboot/Dasharo is the only viable option from what I was able to find. Only Intel ME can be neutered; AMD, Apple Silicon or mobiles not possible. You can buy ME neutered laptops, desktops and/or servers here 
shop.nitrokey.com
Products | shop.nitrokey.com